{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/advanced-responsive-video-embedder-for-rumble-odysee-youtube-vimeo-kick--plugin-10.8.7/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-18072"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin (10.8.7)"],"_cs_severities":["critical"],"_cs_tags":["wordpress","authentication-bypass","web-vulnerability"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eCVE-2026-18072 identifies a critical authentication bypass vulnerability in version 10.8.7 of the Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress. This flaw arises from a hardcoded backdoor within the \u003ccode\u003e_arve_uc_init()\u003c/code\u003e function, which is registered on WordPress's \u003ccode\u003einit\u003c/code\u003e hook with priority 1, ensuring it executes before standard authentication checks. Unauthenticated attackers can exploit this by supplying a specific, hardcoded SHA-256 token via the \u003ccode\u003e_wplogin\u003c/code\u003e or \u003ccode\u003e_wpm\u003c/code\u003e URL parameter. The function compares the provided token against the static hash embedded directly in the plugin's source code, completely bypassing nonce verification, capability checks, and password validation. This allows attackers to authenticate as any existing administrator account, thereby achieving full administrative control over the affected WordPress site. The presence of this backdoor suggests it may have been maliciously introduced by an attacker who gained commit access to the plugin developers' account.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a target WordPress site running the Advanced Responsive Video Embedder plugin version 10.8.7.\u003c/li\u003e\n\u003cli\u003eAttacker obtains the publicly known hardcoded SHA-256 hash (acting as universal credentials) from the plugin's source code.\u003c/li\u003e\n\u003cli\u003eAttacker crafts an HTTP GET or POST request targeting the vulnerable WordPress instance.\u003c/li\u003e\n\u003cli\u003eThe request includes a URL query parameter, either \u003ccode\u003e_wplogin\u003c/code\u003e or \u003ccode\u003e_wpm\u003c/code\u003e, containing the hardcoded SHA-256 token.\u003c/li\u003e\n\u003cli\u003eThe WordPress \u003ccode\u003einit\u003c/code\u003e hook triggers the \u003ccode\u003e_arve_uc_init()\u003c/code\u003e function, which processes the attacker-supplied token from the URL parameter.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003e_arve_uc_init()\u003c/code\u003e function validates the provided token against the internally hardcoded SHA-256 hash, bypassing all legitimate authentication mechanisms.\u003c/li\u003e\n\u003cli\u003eThe attacker is successfully authenticated as an arbitrarily selected existing administrator account on the WordPress site without needing valid credentials.\u003c/li\u003e\n\u003cli\u003eAttacker gains full administrative control, enabling actions such as content modification, plugin/theme installation, data exfiltration, or further compromise of the web server.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-18072 grants unauthenticated attackers full administrative control over the affected WordPress site. This can lead to severe consequences including, but not limited to, complete website defacement, arbitrary code execution, exfiltration of sensitive data, creation of new malicious administrator accounts for persistence, and the use of the compromised site as a platform for further attacks (e.g., malware distribution, phishing campaigns). The exact number of victims is not specified, but any organization utilizing the vulnerable plugin version is at critical risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003ePatch CVE-2026-18072 immediately\u003c/strong\u003e by updating the \u0026quot;Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick …\u0026quot; plugin to a version greater than 10.8.7.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eDeploy the Sigma rule below\u003c/strong\u003e to your SIEM to detect exploitation attempts of CVE-2026-18072, ensuring webserver logs are collected.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eReview webserver access logs\u003c/strong\u003e for the presence of \u003ccode\u003e_wplogin\u003c/code\u003e or \u003ccode\u003e_wpm\u003c/code\u003e query parameters, as indicated in the Sigma rule.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-29T05:21:46Z","date_published":"2026-07-29T05:21:46Z","id":"https://feed.craftedsignal.io/briefs/2026-07-wordpress-arve-bypass/","summary":"A critical authentication bypass vulnerability, CVE-2026-18072, affects version 10.8.7 of the Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress, allowing unauthenticated attackers to gain full administrative control by supplying a hardcoded token via the `_wplogin` or `_wpm` URL parameter.","title":"Authentication Bypass in Advanced Responsive Video Embedder WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-07-wordpress-arve-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … Plugin (10.8.7)","version":"https://jsonfeed.org/version/1.1"}